18.5.20.1 Ensure 'Configuration of wireless settings using Windows Connect Now' is set to 'Disabled' - DisableUPnPRegistrar

Information

This policy setting allows the configuration of wireless settings using Windows Connect Now (WCN). The WCN Registrar enables the discovery and configuration of devices over Ethernet (UPnP) over in-band 802.11 Wi-Fi through the Windows Portable Device API (WPD) and via USB Flash drives. Additional options are available to allow discovery and configuration over a specific medium.

The recommended state for this setting is: 'Disabled'.

Rationale:
This setting enhances the security of the environment and reduces the overall risk exposure related to user configuration of wireless settings.

Solution

To establish the recommended configuration via GP, set the following UI path to 'Disabled:'


Computer Configuration\Policies\Administrative Templates\Network\Windows Connect Now\Configuration of wireless settings using Windows Connect Now


Note: This Group Policy path is provided by the Group Policy template 'WindowsConnectNow.admx/adml' that is included with all versions of the Microsoft Windows Administrative Templates.

Impact:
WCN operations are disabled over all media.

See Also

https://workbench.cisecurity.org/files/1949

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CCE|CCE-37481-9, CSCv6|9.1, CSCv6|15.4

Plugin: Windows

Control ID: 18fc36decba7fd4c452c9971c5c4e9194a9f43a0b1eb9d6209e0438017899aa5